CVE-2010-3695

Exp

Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration.

Published: 2011-03-31 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-3695 is rated High Exploit Risk (67.9/100): CVSS Medium severity, with high exploitation likelihood (EPSS 4.98%, 91th percentile). Core evidence: 7 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +3.81% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2010-3695

EDB-ID Source Kind Published Link
34773 exploit_db edb 2010-09-27 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2010-3695

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 1.17% 4.98% +3.81%
2 2025-12-08 1.26% 1.17% -0.09%
3 2025-07-18 1.26%

Full EPSS history (16 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-3695

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2010-3695

OS Trackers for CVE-2010-3695

vendor priority summary link
ubuntu medium CVE-2010-3695 medium priority: Ubuntu including 1 source packages (imp4), 12 status rows across 12 suites (dapper, hardy, karmic, lucid, maverick, natty, oneiric, precise, quantal, raring, saucy, upstream): ignored 5, not-affected 4, DNE 2, released 1. https://ubuntu.com/security/CVE-2010-3695

Affected software / configurations for CVE-2010-3695

Vendor Product Version Raw CPE
horde imp <= 4.3.7 cpe:2.3:a:horde:imp:*:*:*:*:*:*:*:*
horde imp 2.0 cpe:2.3:a:horde:imp:2.0:*:*:*:*:*:*:*
horde imp 2.2 cpe:2.3:a:horde:imp:2.2:*:*:*:*:*:*:*
horde imp 2.2.1 cpe:2.3:a:horde:imp:2.2.1:*:*:*:*:*:*:*
horde imp 2.2.2 cpe:2.3:a:horde:imp:2.2.2:*:*:*:*:*:*:*
horde imp 2.2.3 cpe:2.3:a:horde:imp:2.2.3:*:*:*:*:*:*:*
horde imp 2.2.4 cpe:2.3:a:horde:imp:2.2.4:*:*:*:*:*:*:*
horde imp 2.2.5 cpe:2.3:a:horde:imp:2.2.5:*:*:*:*:*:*:*
horde imp 2.2.6 cpe:2.3:a:horde:imp:2.2.6:*:*:*:*:*:*:*
horde imp 2.2.7 cpe:2.3:a:horde:imp:2.2.7:*:*:*:*:*:*:*
horde imp 2.2.8 cpe:2.3:a:horde:imp:2.2.8:*:*:*:*:*:*:*
horde imp 2.3 cpe:2.3:a:horde:imp:2.3:*:*:*:*:*:*:*
horde imp 3.0 cpe:2.3:a:horde:imp:3.0:*:*:*:*:*:*:*
horde imp 3.1 cpe:2.3:a:horde:imp:3.1:*:*:*:*:*:*:*
horde imp 3.1.2 cpe:2.3:a:horde:imp:3.1.2:*:*:*:*:*:*:*
horde imp 3.2 cpe:2.3:a:horde:imp:3.2:*:*:*:*:*:*:*
horde imp 3.2.1 cpe:2.3:a:horde:imp:3.2.1:*:*:*:*:*:*:*
horde imp 3.2.2 cpe:2.3:a:horde:imp:3.2.2:*:*:*:*:*:*:*
horde imp 3.2.3 cpe:2.3:a:horde:imp:3.2.3:*:*:*:*:*:*:*
horde imp 3.2.4 cpe:2.3:a:horde:imp:3.2.4:*:*:*:*:*:*:*
horde imp 3.2.5 cpe:2.3:a:horde:imp:3.2.5:*:*:*:*:*:*:*
horde imp 3.2.6 cpe:2.3:a:horde:imp:3.2.6:*:*:*:*:*:*:*
horde imp 3.2.7 cpe:2.3:a:horde:imp:3.2.7:*:*:*:*:*:*:*
horde imp 3.2.7 cpe:2.3:a:horde:imp:3.2.7:rc1:*:*:*:*:*:*
horde imp 4.0 cpe:2.3:a:horde:imp:4.0:*:*:*:*:*:*:*
horde imp 4.0.1 cpe:2.3:a:horde:imp:4.0.1:*:*:*:*:*:*:*
horde imp 4.0.2 cpe:2.3:a:horde:imp:4.0.2:*:*:*:*:*:*:*
horde imp 4.0.3 cpe:2.3:a:horde:imp:4.0.3:*:*:*:*:*:*:*
horde imp 4.0.4 cpe:2.3:a:horde:imp:4.0.4:*:*:*:*:*:*:*
horde imp 4.1.3 cpe:2.3:a:horde:imp:4.1.3:*:*:*:*:*:*:*
horde imp 4.1.5 cpe:2.3:a:horde:imp:4.1.5:*:*:*:*:*:*:*
horde imp 4.1.6 cpe:2.3:a:horde:imp:4.1.6:*:*:*:*:*:*:*
horde imp 4.2 cpe:2.3:a:horde:imp:4.2:*:*:*:*:*:*:*
horde imp 4.2.1 cpe:2.3:a:horde:imp:4.2.1:*:*:*:*:*:*:*
horde imp 4.2.2 cpe:2.3:a:horde:imp:4.2.2:*:*:*:*:*:*:*
horde imp 4.3 cpe:2.3:a:horde:imp:4.3:*:*:*:*:*:*:*
horde imp 4.3.1 cpe:2.3:a:horde:imp:4.3.1:*:*:*:*:*:*:*
horde imp 4.3.2 cpe:2.3:a:horde:imp:4.3.2:*:*:*:*:*:*:*
horde imp 4.3.3 cpe:2.3:a:horde:imp:4.3.3:*:*:*:*:*:*:*
horde imp 4.3.4 cpe:2.3:a:horde:imp:4.3.4:*:*:*:*:*:*:*
horde imp 4.3.5 cpe:2.3:a:horde:imp:4.3.5:*:*:*:*:*:*:*
horde imp 4.3.6 cpe:2.3:a:horde:imp:4.3.6:*:*:*:*:*:*:*
horde groupware <= 1.2.6 cpe:2.3:a:horde:groupware:*:*:*:*:*:*:*:*
horde groupware 1.0 cpe:2.3:a:horde:groupware:1.0:*:*:*:*:*:*:*
horde groupware 1.0 cpe:2.3:a:horde:groupware:1.0:rc1:*:*:*:*:*:*
horde groupware 1.0 cpe:2.3:a:horde:groupware:1.0:rc2:*:*:*:*:*:*
horde groupware 1.0.1 cpe:2.3:a:horde:groupware:1.0.1:*:*:*:*:*:*:*
horde groupware 1.0.2 cpe:2.3:a:horde:groupware:1.0.2:*:*:*:*:*:*:*
horde groupware 1.0.3 cpe:2.3:a:horde:groupware:1.0.3:*:*:*:*:*:*:*
horde groupware 1.0.4 cpe:2.3:a:horde:groupware:1.0.4:*:*:*:*:*:*:*
horde groupware 1.0.5 cpe:2.3:a:horde:groupware:1.0.5:*:*:*:*:*:*:*
horde groupware 1.0.6 cpe:2.3:a:horde:groupware:1.0.6:*:*:*:*:*:*:*
horde groupware 1.0.7 cpe:2.3:a:horde:groupware:1.0.7:*:*:*:*:*:*:*
horde groupware 1.0.8 cpe:2.3:a:horde:groupware:1.0.8:*:*:*:*:*:*:*
horde groupware 1.1 cpe:2.3:a:horde:groupware:1.1:*:*:*:*:*:*:*
horde groupware 1.1 cpe:2.3:a:horde:groupware:1.1:rc1:*:*:*:*:*:*
horde groupware 1.1 cpe:2.3:a:horde:groupware:1.1:rc2:*:*:*:*:*:*
horde groupware 1.1 cpe:2.3:a:horde:groupware:1.1:rc3:*:*:*:*:*:*
horde groupware 1.1 cpe:2.3:a:horde:groupware:1.1:rc4:*:*:*:*:*:*
horde groupware 1.1.1 cpe:2.3:a:horde:groupware:1.1.1:*:*:*:*:*:*:*
horde groupware 1.1.2 cpe:2.3:a:horde:groupware:1.1.2:*:*:*:*:*:*:*
horde groupware 1.1.3 cpe:2.3:a:horde:groupware:1.1.3:*:*:*:*:*:*:*
horde groupware 1.1.4 cpe:2.3:a:horde:groupware:1.1.4:*:*:*:*:*:*:*
horde groupware 1.1.5 cpe:2.3:a:horde:groupware:1.1.5:*:*:*:*:*:*:*
horde groupware 1.1.6 cpe:2.3:a:horde:groupware:1.1.6:*:*:*:*:*:*:*
horde groupware 1.2 cpe:2.3:a:horde:groupware:1.2:*:*:*:*:*:*:*
horde groupware 1.2 cpe:2.3:a:horde:groupware:1.2:rc1:*:*:*:*:*:*
horde groupware 1.2.1 cpe:2.3:a:horde:groupware:1.2.1:*:*:*:*:*:*:*
horde groupware 1.2.2 cpe:2.3:a:horde:groupware:1.2.2:*:*:*:*:*:*:*
horde groupware 1.2.3 cpe:2.3:a:horde:groupware:1.2.3:*:*:*:*:*:*:*
horde groupware 1.2.3 cpe:2.3:a:horde:groupware:1.2.3:rc1:*:*:*:*:*:*
horde groupware 1.2.4 cpe:2.3:a:horde:groupware:1.2.4:*:*:*:*:*:*:*
horde groupware 1.2.5 cpe:2.3:a:horde:groupware:1.2.5:*:*:*:*:*:*:*

References for CVE-2010-3695

URL Tags
http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0379.html Exploit
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598584 Exploit Patch
http://cvs.horde.org/diff.php/imp/docs/CHANGES?rt=horde&r1=1.699.2.424&r2=1.699.2.430&ty=h
http://git.horde.org/diff.php/groupware/docs/webmail/CHANGES?rt=horde&r1=1.35.2.11&r2=1.35.2.13&ty=h
http://git.horde.org/diff.php/imp/fetchmailprefs.php?rt=horde&r1=1.39.4.10&r2=1.39.4.11 Patch
http://lists.horde.org/archives/announce/2010/000558.html Patch
http://lists.horde.org/archives/announce/2010/000568.html
http://openwall.com/lists/oss-security/2010/09/30/7 Exploit Patch
http://openwall.com/lists/oss-security/2010/09/30/8 Exploit Patch
http://openwall.com/lists/oss-security/2010/10/01/6 Patch
http://secunia.com/advisories/41627 Vendor Advisory
http://secunia.com/advisories/43896 Vendor Advisory
http://securityreason.com/securityalert/8170
http://www.debian.org/security/2011/dsa-2204
http://www.securityfocus.com/archive/1/513992/100/0/threaded
http://www.securityfocus.com/bid/43515 Exploit
http://www.vupen.com/english/advisories/2010/2513 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0769 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=641069 Exploit Patch
cvelogic Threat Intelligence